Establishing secure connection…Loading editor…Preparing document…

Healthcare HIPAA Basics

This template is fully customizable. Edit the text, fill out the fields, and send it for signature. Give it a try!

Healthcare HIPAA Basics

This document contains two distinct components: (1) Acknowledgment of Receipt of the Notice of Privacy Practices and (2) Authorization for Use and Disclosure of Protected Health Information (PHI). By completing and signing this form, the patient or the patient's authorized representative documents their selection(s), authorizations, and understanding of rights under the federal Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule.

Patient Identification

Insurance Information

Medical History (Brief)

Acknowledgment of Notice of Privacy Practices

I acknowledge that I have been offered a copy of the Notice of Privacy Practices that describes how my protected health information may be used and disclosed, and how I can obtain access to this information. I understand that the Notice contains information about my rights and the duties of the practice with respect to my PHI.

Authorization to Use and Disclose Protected Health Information

I authorize the release of my PHI as specified below. This authorization is voluntary. I understand that treatment, payment, enrollment in a health plan, or eligibility for benefits may not be conditioned on my signing this authorization except where permitted by law.

Provide the name(s) and relationship(s) of individuals or organizations permitted to receive your PHI. If you are authorizing release to more than three recipients, attach additional pages containing the same details.

Important: Special categories of information described above (such as HIV status, substance abuse treatment, or psychotherapy notes) may be subject to additional protections under law. If you authorize release of these categories, you explicitly consent by checking the applicable boxes above.

Expiration and Revocation

This authorization will expire on the earlier of the date indicated below or upon the occurrence of the following event: treatment completion, one year from signing, or as otherwise noted. I understand I may revoke this authorization at any time by submitting a written revocation to the practice's privacy officer, except to the extent that the practice has already taken action in reliance on this authorization.

Patient Rights and Notices

I understand that:

  • I may inspect or obtain a copy of the PHI described in this authorization in accordance with applicable law.
  • I may refuse to sign this authorization. My refusal will not affect my ability to obtain treatment, payment, or eligibility for benefits unless the information is necessary to determine those matters.
  • I may revoke this authorization in writing at any time, except to the extent the practice or other covered entity has acted in reliance on it.
  • Information disclosed pursuant to this authorization may be subject to redisclosure by the recipient and may no longer be protected by federal privacy regulations.

I certify that I have read and understand the above statements and that the information I have provided on this form is true to the best of my knowledge.

Patient Printed Name:

If not patient, Representative Name:

Signature:

Date:

Relationship:

By signing above, I attest that I am the patient or I am authorized to sign on behalf of the patient. I understand that a copy of this signed authorization is as valid as the original.

Enter text✕

What Healthcare HIPAA Basics covers

Healthcare HIPAA Basics explains the core elements of HIPAA-compliant patient authorizations and related documentation used by covered entities and business associates. It summarizes required content for valid authorizations, common timing and retention rules, signature and authentication options, and how electronic signatures interact with HIPAA and federal e-signature law to create enforceable records.

Why clear HIPAA authorizations matter

Clear, complete HIPAA authorizations protect patient privacy, reduce legal risk, and ensure lawful disclosures of protected health information. Properly executed forms support audits, breach responses, and consistent data-sharing between providers and business associates.

Why clear HIPAA authorizations matter

Who typically prepares and signs these HIPAA forms

Covered entities, health systems, clinics, and business associates generally prepare HIPAA authorization forms before sharing patient information or responding to requests.

  • Healthcare providers and clinics: Clinical staff or privacy officers prepare and track signed authorizations.
  • Health plan administrators: Use authorizations to coordinate benefits and release claims information.
  • Business associates: Vendors receive and store authorizations when processing PHI on behalf of covered entities.

Individuals sign or revoke authorizations; designated representatives sign when permitted by state law or patient instruction.

Core components of a professional HIPAA authorization

A compliant HIPAA authorization uses clear language and specific fields so both parties understand what PHI will be shared, why, with whom, and for how long.

Patient identity

Full legal name and unique identifier such as medical record number or date of birth to unambiguously link authorization to a specific patient.

Description of PHI

A precise description of the information to be disclosed (e.g., 'clinic notes from 01/01/2020–12/31/2020' or 'lab results for hepatitis C').

Purpose of disclosure

The specific purpose or need for disclosure (treatment, payment, legal, research) so the scope is limited and documented.

Recipient details

Name and contact of the person or organization authorized to receive PHI, including address or secure transmission instructions.

Expiration or event

A clear expiration date or specific event (e.g., 'until completion of claim') after which the authorization is no longer effective.

Signature and date

Signature of the individual or authorized representative and signature date; include statement of authority when signed by representative.

Step-by-step: completing a HIPAA authorization

Follow these sequential steps to prepare, obtain, and record a valid HIPAA authorization for disclosure of PHI.

  • 01
    Prepare the form: Populate patient identifiers, PHI description, recipient, purpose, and expiration.
  • 02
    Explain consent: Provide required consumer disclosure and answer patient questions before signature.
  • 03
    Obtain signature: Have the patient or authorized representative sign and date the document.
  • 04
    Record and store: Store the signed authorization in the medical record and log access for audit.

Configuring a digital HIPAA authorization workflow

Design workflow settings to ensure authentication, auditability, and secure routing of signed authorizations.

Field Configuration
Authentication level Use at least email plus SMS or ID verification for high-sensitivity disclosures.
Document retention Set automated retention to 6 years to align with HIPAA 45 CFR §164.530(j).
Audit trail Enable IP, timestamp, and signer attribution logging for every signature event.
Access controls Limit who can view or resend authorizations using role-based permissions.

Where to send and file completed authorizations

Routing and filing practices differ by organization; standardize destinations for consistency and compliance.

  • Medical record: Save a signed copy to the patient's electronic health record for auditability and continuity.
  • Recipient delivery: Send the authorized PHI to the named recipient using the requested secure method.
  • Privacy office: Provide a copy to your privacy or compliance office for monitoring and retention.
  • Business associate: Attach the authorization to any transmission when a business associate processes PHI on your behalf.

Digital signing and platform requirements

Use platforms that support secure transmission, audit trails, and HIPAA Business Associate Agreements when required.

  • Encryption: TLS 1.2/1.3 in transit; AES-256 at rest.
  • Authentication: Support for SMS, email, KBA, or stronger ID methods.
  • Integrations: Connectors for EHR, cloud storage, and SSO reduce manual handling.

Confirm the vendor will sign a Business Associate Agreement (BAA) and provide an auditable certificate of completion and access logs.

Key timing and response deadlines to track

Observe statutory response and notification windows to remain compliant and reduce regulatory risk.

Access request response:

Respond to individual access requests within 30 days (45 CFR §164.524(b)(2)).

Breach notification:

Notify affected individuals without unreasonable delay, no later than 60 days after discovery (45 CFR §164.404).

Authorization expiration:

Honor the expiration date specified; if none, treat with conservatively limited scope.

Revocation effective date:

Revocation is effective upon receipt but does not undo disclosures already made.

Retention minimum:

Maintain authorizations for six years from creation or last effective date (45 CFR §164.530(j)).

Common mistakes that lead to invalid authorizations

  • Using vague PHI descriptions that do not permit a recipient to identify the records to be disclosed.
  • Omitting an expiration date or event, leaving the authorization open-ended and subject to challenge.
  • Accepting inconsistent signer identity without verification, causing attribution disputes during audits.
  • Failing to record revocations promptly, resulting in continued disclosures after the patient rescinds consent.

Penalties and legal risks of improper HIPAA authorizations

Civil money penalties: Fines under HIPAA enforcement
OCR enforcement: Corrective action plans possible
State tort claims: Potential privacy-related lawsuits
Malpractice exposure: Increased liability for improper disclosures
Regulatory audits: Heightened scrutiny and reporting
Business disruption: Operational costs and remediation

eSignature pricing and capability overview for HIPAA workflows

Compare starting prices and core features relevant to HIPAA workflows; confirm HIPAA/BAA availability directly with each vendor before purchase.

signNow DocuSign Adobe Sign PandaDoc HelloSign
Starting Price $8/user/mo $15/user/mo $14/user/mo $19/user/mo $15/user/mo
Free Trial 7-day free trial, no credit card Varies by vendor Varies by vendor Varies by vendor Varies by vendor
Bulk Send Yes Yes Yes Yes No
Audit Trail Yes Yes Yes Yes Yes
HIPAA Compliant Yes Yes Yes No No
Envelope Cap No envelope cap 100 envelopes/user/year Varies Varies Varies

FAQs: practical answers about HIPAA authorizations and e-signatures

Answers to common questions about legal validity, electronic signatures, BAAs, revocation, authentication options, and recordkeeping.


Need help? Contact support

be ready to get more
Join over 28 million airSlate SignNow users